Home / What we do / Domain & DNS
Hosting · Domain & DNS

The internet's address book, kept current.

Domain registration, transfer, and managed DNS on anycast resolvers. DNSSEC, fast TTLs, and the records-management discipline that prevents the 'who broke MX?' email thread.

Editorial still-life photograph for the Domain & DNS service
What's included

DNS, treated like the production system it is.

DNS is the most-overlooked, most-broken-by-amateurs piece of every modern company. It's also the layer everything else depends on: the website, the email, the VPN, the portal. We treat it as load-bearing, which means it gets documentation, access control, and a renewal calendar, not a sticky note and a hope.

R

Registration + transfer

Domain renewals tracked on a calendar a human actually watches, and transfers done without losing the keys. EPP authorization codes and registrar logins are held securely, not floating in someone's personal inbox waiting to be the reason a domain walks away.

A

Anycast DNS

Global anycast resolvers answer from the point of presence closest to the visitor, so resolution is fast under load and the same name resolves quickly from anywhere. The distributed design also makes the zone hard to knock off the internet with a DDoS.

S

DNSSEC

Signed zones with managed key rotation, the cryptographic layer that stops your records being forged or lied about between the resolver and the client. It's the difference between a visitor reaching you and a visitor reaching whoever poisoned the answer.

H

Records hygiene

SPF, DKIM, DMARC, MX, CNAME, the records nobody documents until they break and email stops flowing. We document every one, explain what it does, and keep them current as your email and services change.

L

Sensible TTLs

Time-to-live values set deliberately: long enough for cache efficiency, short enough that a change or a failover propagates in minutes instead of a day. We lower them ahead of planned changes so cutovers are fast and reversible.

M

Change management

DNS changes are made carefully, by people who know what depends on each record, with the dependent records (like SPF when MX moves) updated in the same breath. No more solo edits at 5pm that take down email until morning.

DNS is where small mistakes become large outages.

Most of the worst outages we've cleaned up after weren't application failures. They were DNS. Someone updated a record and forgot the matching SPF, so email started bouncing. Someone set a 24-hour TTL and then needed to fail over, so the fix took a day to reach anyone. Someone let the domain quietly expire, and the company vanished from the internet over a weekend. None of these are exotic. They're the ordinary result of treating DNS as a settings page rather than a production system, and the cost is usually a day or two of unreachable email plus the harder-to-measure damage of customers finding you offline.

The fix is unglamorous and durable. We move the DNS onto managed anycast resolvers, document every record and what depends on it, set TTLs deliberately, and put the renewal dates somewhere a person will actually see them before they pass. Then changes go through people who understand the blast radius of each edit. Because DNS is also where your email authentication records live and where your website address resolves, getting this layer right quietly improves the reliability of nearly everything sitting on top of it.

The single best thing they did the first month was move our DNS off the registrar's nameservers. Resolution dropped to single digits.
How it works

From scattered records to a managed zone.

Taking over DNS is a careful, reversible process. The goal is to move the zone without a single record dropping a beat, then keep it that way.

01

Inventory

We pull and document every existing record (A, CNAME, MX, TXT, SPF, DKIM, DMARC, and the odd ones) and map what each one points at, so nothing gets left behind in the move and nothing surprises us later.

02

Stage

We build the zone on managed anycast nameservers as an exact copy, lower the TTLs on the current setup ahead of time, and review the new zone against the inventory record by record before anything points at it.

03

Cut over

We update the nameservers at the registrar, watch propagation roll out, and confirm email, web, and every service still resolve correctly. Because TTLs were lowered first, the switch is quick and easy to reverse.

04

Maintain

From there: tracked renewals, DNSSEC signing and key rotation, documented changes, and the records kept current as services move. The "who broke MX?" thread stops happening because someone owns the zone now.

Who it's for.

Managed domain and DNS fits any business whose website and email are how customers reach them, which is to say nearly all of them, but it matters most for the ones who've been bitten or are one mistake away from it. That's the company whose domain registration is in a former employee's personal account, the organization whose DNS is a tangle of records nobody fully understands managed at three different providers, the business that's lost email for a day after a well-meaning edit, and the team about to migrate a website or email platform and dreading the cutover. It also fits regulated practices that need DNSSEC and correct email-authentication records as part of a defensible posture. If your domain renewal is a date you hope someone remembers, or if your DNS lives at the same low-bid registrar as your hosting with no documentation, this puts the address book of your business on solid ground. It pairs naturally with web hosting, the destination most records point at, and with email security, since SPF, DKIM, and DMARC are DNS records that have to be correct for mail to be trusted.

Questions

Common questions about domain and DNS.

Will moving my DNS cause downtime for my website or email?

It shouldn't. We copy every existing record exactly, lower the time-to-live values ahead of the switch, then change nameservers and watch propagation roll out while confirming web and email still resolve. Because the change is staged and the TTLs are low, it's quick and reversible. Done this way, the move is invisible to your visitors and your inbox.

What is DNSSEC and do I need it?

DNSSEC cryptographically signs your DNS records so a resolver can verify the answer it gets is genuinely yours and hasn't been forged in transit. Without it, an attacker who poisons a DNS answer can quietly redirect your visitors or mail. It's increasingly expected for regulated and security-conscious organizations, and we handle the signing and key rotation for you, so it's protection without the operational headache.

Can you manage a domain registered somewhere else?

Yes. We can either transfer the domain to a registrar we manage or leave it where it is and just take over the DNS by pointing the nameservers at our anycast platform. Either way we track the renewal so it can't lapse, and we secure the registrar access and authorization codes so the domain can't be moved or lost without your knowledge.

Why does DNS need managing at all?

Because it's load-bearing and easy to break. Your website, email, VPN, and portal all depend on correct DNS records, and a single careless edit (a wrong MX, a forgotten SPF, an expired domain) can take services offline for hours or days. Managing it means documentation, sensible TTLs, change discipline, and a renewal calendar, so small mistakes stop turning into large outages.

How does this relate to email deliverability?

Closely. SPF, DKIM, and DMARC are all DNS records, and when they're wrong or missing, your legitimate email lands in spam or gets rejected while spoofers impersonate your domain. We keep those records correct and aligned, which is half the battle for deliverability. It works alongside email security, which handles the filtering and the policy side of the same problem.

Schedule a call

Let's talk for 30 minutes.
No slides.

Send us your apex domain. We'll come back with a written zone audit, what's misconfigured, what's missing, and what we'd change first.

  • 30-min discovery, no slide deck
  • Free written assessment, yours to keep
  • A clear proposal, no pressure

Or call us directly: 904-639-0003

Schedule a call →